write-incident-postmortem

Generate structured incident postmortems with executive summaries, timelines, and root cause analysis.

1|Updated Feb 16, 2026
One-click install
npx skills add https://github.com/constellize/marketplace --skill write-incident-postmortem
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: write-incident-postmortem
Source: https://github.com/constellize/marketplace/tree/main/plugins/constellize-operations/skills/write-incident-postmortem
Command: npx skills add https://github.com/constellize/marketplace --skill write-incident-postmortem

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Incident postmortems document and synthesize learnings from outages to drive systemic improvements and prevent recurrence.

Core Features & Use Cases

  • Executive summary generation capturing the incident overview, impact, and recommended actions.
  • Detailed timeline reconstruction with decision points, actions taken, and evidence.
  • Root cause analysis identifying immediate cause, contributing factors, and systemic issues.
  • Actionable prevention, remediation, and follow-up plans with owners and due dates.
  • Cross-reference updates and documentation linkage to runbooks, architecture, and past incidents.

Quick Start

Describe the incident details (system, incident ID, start time, end time, severity, and a brief impact summary) to generate a complete postmortem.

Frequently Asked Questions about write-incident-postmortem

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write an incident postmortem for a Sev-1 outage?

To write an incident postmortem for a Sev-1 outage, input the system, incident ID, start and end times, severity, and impact summary to generate a structured document with an executive summary, timeline, root cause analysis, and remediation plan.

What should be included in a blameless root cause analysis for incident response?

A blameless root cause analysis should include the immediate cause, contributing factors, and systemic issues. It reconstructs the timeline with decision points and evaluates the incident response to identify actionable prevention steps without assigning individual blame.

How do I generate remediation plans with owners and due dates after an incident?

You generate remediation plans with owners and due dates by synthesizing the incident timeline and root cause analysis into actionable prevention steps, ensuring cross-reference updates link directly to relevant runbooks and architecture documentation.

Can I use this structured postmortem format for systems beyond Sev-1 outages?

Yes, you can use this structured postmortem format for systems beyond Sev-1 outages. While it applies to Sev-1 incidents, the structured sections like executive summary, RCA, and response evaluation capture learnings for any system failure.

What is the best way to document protective factors and response evaluation in a postmortem?

The best way to document protective factors and response evaluation in a postmortem is to systematically review the actions taken during the incident timeline, capturing what mitigated impact and identifying systemic strengths alongside root causes.

Why do incident postmortems need cross-reference links to runbooks and past investigations?

Incident postmortems need cross-reference links to runbooks and past investigations to drive systemic improvements, maintain documentation linkage across architecture, and ensure remediation plans prevent recurrence by connecting to operational knowledge.